First published: Mon Aug 12 2019(Updated: )
The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wpdeveloper Twitter Cards Meta | <2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18503 is a vulnerability in the twitter-cards-meta plugin before version 2.5.0 for WordPress that allows for cross-site scripting (XSS) attacks.
CVE-2017-18503 has a severity rating of 6.1, which is considered medium.
CVE-2017-18503 affects WordPress by allowing for cross-site scripting (XSS) attacks through the twitter-cards-meta plugin before version 2.5.0.
Yes, to fix CVE-2017-18503, users should update the twitter-cards-meta plugin to version 2.5.0 or later.
You can find more information about CVE-2017-18503 on the official WordPress plugin page: https://wordpress.org/plugins/twitter-cards-meta/#developers